[SOLVED] Failing connection to pbs after setting a custom certificate in it.

Problem resolved, I report here my comment 2 in bug 4207:
Thanks! I installed only the leaf (the pbs server cert) and it works.

After that, i installed on pbs the complete chain (so the web gui is accessible without ssl exceptions). In order to let pve nodes to validate the chain, i installed the root ca (in PEM format) in /usr/local/share/ca-certificates/ on each pve node, running update-ca-certificate afterwards, so that our root being accepted by the system as a trusted one.

Problem resolved. Maybe the custom root should be part of the pve cluster fs, in order to propagate it cluster-wide, as other configuration?

Alternatively, maybe adding the fingerprint should work even for non self-signed custom certs?

Thanks,
rob
 
Note that no fingerprint is needed in pbs storage config, if the root is trusted by pve host.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!